GKE 1.36 changelog

This document lists the changes for the patch versions of the Google Kubernetes Engine (GKE) 1.36 minor version.

These changelogs are supplementary information about the updates to specific GKE system components. For information about features, changes, and security issues in GKE, see the following documents:

1.36.4-gke.1495000

The following sections describe changes in this patch version when compared with the previous patch version, 1.36.4-gke.1391000. For information about upstream Kubernetes changes, see the Kubernetes v1.36.4 changelog.

Kubernetes Updates

k8s-api

Updated k8s-api cohort from version 1.36.4-gke.200 to 1.36.4-gke.400.

  • Miscellaneous:
    • Updated the Go runtime and container base images for the 1.36 branch.

Component Updates

The following sections provide information about updates to specific GKE system components in this patch version.

clouddns

Updated clouddns component from version 36.3.3 to 36.3.5.

  • Bug Fixes:
    • Cloud DNS Controller: Improved shutdown logic for Cloud DNS controllers in multi-tenant environments. This ensures reconcilers, updaters, and informers are properly cleaned up when a controller shuts down, preventing resource leaks. (Fixes )

filestorecsi

Updated filestorecsi component from version 1.36.19 to 1.36.20.

gcp-controller-manager-combined

Updated gcp-controller-manager-combined component from version 36.2.0 to 36.2.3.

  • Features:
    • Added support in nodeannotator to populate TPU partition topology labels for TPU8i.
  • Security Fixes:
    • Updated github.com/google/cel-go to v0.29.2 to address security vulnerability GHSA-gcjh-h69q-9w9g.
  • Miscellaneous:
    • Updated the flag name for custom signer name delegation to allow-signing-kubelet-serving-for-non-gcp.
    • Updated the configuration flag for custom signerName delegation to allow-signing-kubelet-serving-for-non-gcp.
    • Updated the gcp-controller-manager container image.

gcsfusecsi

Updated gcsfusecsi component from version 1.36.42 to 1.36.43.

  • Security Fixes:
    • Updated Go modules, base images, and the csi-node-driver-registrar component to address security vulnerabilities.
  • Miscellaneous:
    • Updated Go runtime to version 1.27.1.

gke-metrics-agent

Updated gke-metrics-agent component from version 2.136.20-gke.1 to 2.136.20-gke.3.

  • Features:
    • Implemented node-daemon Pressure Stall Information (PSI) collection.
    • Added support for Pressure Stall Information (PSI) collection for node daemons.
  • Miscellaneous:
    • Optimized the container image size by refining vendor dependency management following Prometheus upgrades.
    • Updated configuration to include Starlark options files.
    • Updated Workload Autoscaler to version 0.27.0-gke.18.

gvisor

Updated gvisor component from version 1.36.23 to 1.36.24.

  • Miscellaneous:
    • Updated the container base image.

kube-controller-manager

Updated kube-controller-manager component from version 8.1.0 to 8.1.3.

  • Miscellaneous:
    • Updated configuration to include the options.star Starlark file.

kubedns

Updated kubedns component from version 36.0.3 to 36.0.5.

  • Features:
    • Added configuration support for automating KubeDNS cluster IP calculation for single-stack IPv6 and IPv4 clusters.
  • Bug Fixes:
    • Refined memory request and limit logic to scale dynamically based on the DNS engine type and control plane node size.
  • Security Fixes:
  • Miscellaneous:
    • Introduced a migration guard for Autopilot clusters utilizing Cloud DNS at cluster scope with Dataplane V2.
    • Updated component options to include imports for monitoring endpoints and project-specific metadata.

managed-opentelemetry

Updated managed-opentelemetry component from version 1.36.21-gke.2 to 1.36.21-gke.3.

  • Miscellaneous:
    • Updated the custom OpenTelemetry collector image to version 0.153.0-gke.5.

networkpolicy-calico

Updated networkpolicy-calico component from version 4.36.1 to 4.36.2.

  • Security Fixes:
    • Updated the Go runtime to v1.25.12 and the golang.org/x/crypto module to v0.52.0 to resolve CVE-2026-39822.

nodelocaldns

Updated nodelocaldns component from version 36.1.2 to 36.1.5.

  • Security Fixes:
    • Updated Go modules to address security vulnerabilities.

pdcsi

Updated pdcsi component from version 1.36.24 to 1.36.25.

  • Security Fixes:
    • Updated Go modules, the Go runtime, and container base images to address security vulnerabilities across the Persistent Disk CSI driver and its sidecar components, including csi-resizer, csi-snapshotter, csi-provisioner, and csi-attacher.

tpu-device-plugin

Updated tpu-device-plugin component from version 1.36.7-gke.1 to 1.36.9-gke.0.

  • Features:
    • Update ACS Agent image to include FatalErrorInfo and TPU Halt diagnostic collection.
    • Introduce TPU baremetal node support via --enable-baremetal-mode.
    • Skip MDS partition topology label polling for TPU8i (populated by cloud-provider-gcp).
    • Add multislice network, compute and transfer size/latency metrics.
    • Support enable_full_hierarchy_labels KCP trait.
    • Move ACS Agent (acs-agent) container from tpu-device-plugin DaemonSet to ai-telemetry-collector DaemonSet to prevent guest diagnostic telemetry failures from impacting device plugin health and scheduling availability.
  • Bug Fixes:
    • Add bounds checks for bucket count in TPU device plugin metrics.
    • Restore vbar.sock permission-change log.
    • Revert ACS Agent image to sha256:2c2cad2eff5811c906334bced6a00b6f938d4308a26921bab9f5fc7d7ef445fb to prevent synchronous informer cache sync stalls from blocking TPU device plugin registration and unblock Cluster Autoscaler qualification.
  • Security Fixes:
    • Updated google.golang.org/grpc to version 1.82.1 to address security vulnerability GO-2026-6061.
    • Block vbar.sock symlink privilege escalation by mounting vbar directory read-only into workloads and enforcing safeChmod.
    • Updated runtime base image to gcr.io/distroless/static-debian13 and builder to Golang 1.27.0 to fix base image vulnerabilities.
  • Miscellaneous:
    • Updated the gke-distroless/bash base image.

workloadautoscaler

Updated workloadautoscaler component from version 19.11.0 to 19.14.0.

  • Miscellaneous:
    • Updated Vertical Pod Autoscaler components (admission-controller, recommender, and updater) and the autoscaling-metrics-adapter to version 0.27.0-gke.19.

1.36.4-gke.1391000

The following sections describe changes in this patch version when compared with the previous patch version, 1.36.4-gke.1247000. For information about upstream Kubernetes changes, see the Kubernetes v1.36.4 changelog.

Component Updates

The following sections provide information about updates to specific GKE system components in this patch version.

customer-logs-exporter

Updated customer-logs-exporter component from version 1.36.0-gke.11 to 1.36.0-gke.12.

  • Security Fixes:
    • Updated google.golang.org/grpc to v1.82.1 to resolve security advisory GO-2026-6061.

filestorecsi

Updated filestorecsi component from version 1.36.17 to 1.36.19.

  • Miscellaneous:
    • Updated the Go runtime to version 1.25.11 and refreshed container base images for csi-provisioner, csi-resizer, csi-snapshotter, snapshot-controller, and snapshot-validation-webhook.
    • Updated base images to the latest distroless versions for improved security and stability.
    • Explicitly named an internal initialization container as imgSpnpInitContainer in the component manifest.

gcsfusecsi

Updated gcsfusecsi component from version 1.36.41 to 1.36.42.

  • Miscellaneous:
    • Updated the Go runtime to version 1.27.1 and updated container images for the CSI driver, node driver registrar, sidecar mounter, webhook, and metadata prefetcher.

gpu-device-plugin

Updated gpu-device-plugin component from version 1.36.3-gke.2 to 1.36.5-gke.3.

  • Miscellaneous:
    • bump gpu-device-plugin to v1.36.4-gke.0
    • bump nvidia-partition-gpu to v1.36.4-gke.0
    • bump nvidia-persistenced-installer to v1.36.4-gke.0
    • Updated the gpu-fraction-divisor path to use underscores instead of hyphens.

kube-addon-manager

Updated kube-addon-manager component from version 35.0.2 to 35.0.5.

  • Features:
    • Added support for multi-architecture releases.
  • Miscellaneous:
    • Updated the kubectl prune whitelist to include flow control resources (FlowSchema and PriorityLevelConfiguration) for clusters running Kubernetes 1.23.0 and newer.
    • Added a configuration option to manage leader election modes for the addon manager.

pdcsi

Updated pdcsi component from version 1.36.23 to 1.36.24.

  • Security Fixes:
  • Miscellaneous:
    • Updated the Go runtime to version 1.26.5.
    • Updated the debian-base and distroless-static container base images for the CSI driver, snapshotter, and related sidecar components.

1.36.4-gke.1247000

The following sections describe changes in this patch version when compared with the previous patch version, 1.36.4-gke.1082000. For information about upstream Kubernetes changes, see the Kubernetes v1.36.4 changelog.

Component Updates

The following sections provide information about updates to specific GKE system components in this patch version.

gcp-controller-manager-combined

Updated gcp-controller-manager-combined component from version 36.1.4 to 36.2.0.

  • Features:
    • Added support for the ToLocalhost type within the component configuration.
    • Added the --fetched_cert_validity flag to allow configuration of certificate TTL for fetched credentials.
  • Miscellaneous:
    • Renamed the custom signerName delegation flag to allow-signing-kubelet-serving-for-non-gcp to improve clarity for signing kubelet serving certificates on non-GCP nodes.
    • Removed legacy host-path volume mounts for /etc/srv/kubernetes/pki and associated command-line flags for cluster CA files (--cluster-root-ca-file and --cluster-ca-bundle) in favor of DCD.

gke-metrics-agent

Updated gke-metrics-agent component from version 2.136.20-gke.0 to 2.136.20-gke.1.

  • Features:
    • Implemented Pressure Stall Information (PSI) collection for node daemons.
  • Miscellaneous:
    • Reduced the container image size by optimizing vendor dependency trimming.

l7-lb-controller-combined

Updated l7-lb-controller-combined component from version 1.41.3-gke.0 to 1.41.4-gke.0.

  • Features:
    • Added support for BYOIPv6 NetLB via the ip-collection-v6 annotation.
  • Bug Fixes:
    • Improved Standalone NEG LB controller with better event messaging, rule sorting, IP sanitization, and user error classification (including BackendNotAttached condition).
    • Allowed static BYOIPv6 addresses without the ip-collection-v6 annotation, and added a warning when the annotation is mistakenly used on an ILB.
    • Refactored L4 standalone NEG controller logic.
  • Security Fixes:
    • Addressed a Confused Deputy vulnerability in the Standalone NEG controller by verifying that service NEGs are attached to the LB backend service before writing the LB VIP into the service status.

osimage

Updated osimage component from version 1.36.95 to 1.36.99.

  • Security Fixes:
  • Miscellaneous:
    • Updated system packages and dependencies: containerd and containerd-test to v2.2.7, fluent-bit to v4.2.8, unzip to v6.0_p31, dash to v0.5.13.5, libverto to v0.3.2-r1, popt to v1.19-r1, acl to v2.4.0-r2, and passwdqc to v2.0.3-r1.
    • Adjusted runtime sysctl configuration for net.ipv4.udp_mem.

1.36.4-gke.1082000

The following sections describe changes in this patch version when compared with the previous patch version, 1.36.3-gke.1767000. For information about upstream Kubernetes changes, see the Kubernetes v1.36.4 changelog.

Component Updates

The following sections provide information about updates to specific GKE system components in this patch version.

customer-logs-exporter

Updated customer-logs-exporter component from version 1.36.0-gke.9 to 1.36.0-gke.11.

  • Security Fixes:
    • Updated google.golang.org/grpc to v1.82.1 to resolve GO-2026-6061.
  • Miscellaneous:
    • Introduced new configuration support for cloud logging endpoints and project-specific metadata via ComponentOptionsConfig.

gke-metrics-agent

Updated gke-metrics-agent component from version 2.136.18-gke.1 to 2.136.20-gke.0.

  • Features:
    • Implemented node-level Pressure Stall Information (PSI) collection.
  • Miscellaneous:
    • Optimized the container image size by adjusting vendor dependencies, reducing the image size from approximately 64MB to 47MB.
    • Updated Workload Autoscaler to version 0.27.0-gke.17.

gvisor

Updated gvisor component from version 1.36.19 to 1.36.23.

  • Miscellaneous:
    • Updated gVisor to version 20260727.0_RC04.

l7-lb-controller-combined

Updated l7-lb-controller-combined component from version 1.41.1-gke.0 to 1.41.3-gke.0.

  • Bug Fixes:
    • Improved L4 Address Manager IP validation to prevent false positive substring matches and enforce explicit Network Tier and Load Balancing Scheme validation.
  • Security Fixes:
    • Go version update to 1.26.6, Go kubernetes client dependency updates to v1.36.3, update google.golang.org/api and google.golang.org/grpc to the newest versions.

osimage

Updated osimage component from version 1.36.75 to 1.36.95.

1.36.3-gke.1767000

The following sections describe changes in this patch version when compared with the previous patch version, 1.36.3-gke.1640000. For information about upstream Kubernetes changes, see the Kubernetes v1.36.3 changelog.

Component Updates

The following sections provide information about updates to specific GKE system components in this patch version.

clouddns

Updated clouddns component from version 36.3.2 to 36.3.3.

  • Bug Fixes:
    • Fix crash loop by mounting tmp as read-write in clouddns container.

gcsfusecsi

Updated gcsfusecsi component from version 1.36.38 to 1.36.41.

  • Security Fixes:
    • Updated golang.org/x/mod from v0.37.0 to v0.40.0 to address security vulnerability GO-2026-6179.

networkpolicy-calico

Updated networkpolicy-calico component from version 4.36.0 to 4.36.1.

  • Security Fixes:
    • Fixed CVE-2026-39822 by updating the Go build version to 1.25.12.
    • Updated golang.org/x/crypto to v0.52.0 to remediate security vulnerabilities in the Calico node component.